Senior Vulnerability Analyst (US)

Posted 20 Days Ago
3 Locations
In-Office or Remote
Mid level
Cybersecurity
Outpace Adversaries
The Role
Analyze diverse threat intelligence sources to identify and validate exploited vulnerabilities, exploits/PoCs, threat actors, malicious infrastructure, and IOCs. Assess source credibility and evidence of real-world exploitation, maintain structured intelligence outputs, and work with structured data formats to support vulnerability and exploit intelligence pipelines.
Summary Generated by Built In
Senior Vulnerability Analyst

Location: MA / Austin TX / MD
Team: Research
Employment Type: Full-Time, Remote

About VulnCheck

Exploitation prevention is only as strong as the intelligence driving those efforts, and most of the industry is still running on intelligence that lacks exploit context. VulnCheck, The Exploit Intelligence Company, delivers structured exploit intelligence on what is actively weaponized in the wild, purpose-built for the data lakes, ETL pipelines, automation, and AI and LLM workflows your infrastructure already runs on, raising the capability of everything it powers.

About the Role

Are you passionate about advancing the science of vulnerability analysis and threat intelligence? Do you want to join a mission-driven team that delivers real-world impact—and has the resources and technical culture to fuel your curiosity?

We’re searching for a Senior Vulnerability Analyst with a deep understanding of the vulnerability management ecosystem, hands-on experience with the CVE process, and expert knowledge in standard frameworks like MITRE ATT&CK, CAPEC, CWE, and CVSS. This is a rare opportunity to leverage your skills and experience as a contributor to, or expert user of, CVE and related MITRE capabilities—while taking your career in vulnerability research to the next level.

We are expanding our Threat Intelligence team and are looking for a detail-oriented analyst to join VulnCheck. This is a 100% remote role with preference for candidates located in Massachusetts, Maryland, OR Greater Austin TX.

What You’ll Do
  • Map vulnerabilities: Analyze and map discovered vulnerabilities to MITRE ATT&CK techniques and CAPEC attack patterns with precision and consistency.
  • CWE assignment: Determine and assign accurate CWE (Common Weakness Enumeration) IDs, producing well-documented rationales.
  • CVSS calculation: Authoritatively calculate CVSS v3/v4 base scores, providing transparent, defensible justifications.
  • CVE Processing: Review, draft, and curate CVE Records, ensuring data quality, fidelity, and consistency with CVE Program standards.
  • Collaboration: Liaise with vulnerability researchers, product security teams, and standards communities to ensure best practices and knowledge transfer.
  • Process improvement: Develop and refine workflows and playbooks for vulnerability triage, mapping, and reporting.
  • Mentorship: Share your expertise by mentoring junior analysts and driving team knowledge-sharing initiatives.
What You’ll Bring
  • Proven experience with the CVE Program—either as an analyst, CNA, or significant contributor in a major software or security organization.
  • Expert knowledge of MITRE ATT&CK, CAPEC, CWE, and working experience mapping vulnerabilities to these frameworks.
  • Advanced understanding of CVSS (v3 and v4), including real-world application to vulnerability scoring and risk communication.
  • Strong analytical, technical, and research skills, with a passion for data quality and process rigor.
  • Exceptional written and verbal communication skills—including the ability to translate complex technical details for diverse audiences.
  • Experience engaging with community initiatives, standards bodies, or open-source projects in the vulnerability or threat intelligence space is highly desirable.

Preferred Qualifications

  • Experience contributing to the evolution of vulnerability standards (e.g., participation in CVE Editorial Boards, CAPEC Working Groups, or similar).
  • Familiarity with automation tools or programming/scripting languages (Python, Golang, etc.) for data enrichment or workflow improvement.
  • Published research, whitepapers, or presentations in the field of vulnerability analysis, mapping, or threat intelligence.

IMPORTANT NOTE: This position may involve access to technology subject to U.S. export control regulations. Employment is contingent upon the company's ability to authorize access under applicable export control, sanctions, and any other applicable legal or contractual requirements. The company does not guarantee and is under no obligation to seek such authorization if it would be necessary.

What We Offer

We believe people do their best work when they feel supported, trusted, and valued. VulnCheck offers benefits designed to meet a wide range of needs and lifestyles:

Benefits and Perks
  • Unlimited PTO
  • 401k plan with company match
  • Comprehensive healthcare coverage
  • Generous paid parental leave
  • Remote friendly environment with flexibility
  • Expense reimbursement for Cell Phone & Internet 
  • Ongoing professional development, coaching, and learning resources
  • Opportunities for career advancement within a fast-growing team
Why Join Us

Built on over two decades of cybersecurity experience, our team of experts understands the intricacies of vulnerabilities, their exploitation in the wild, and how to leverage this data to build more effective cybersecurity products that produce better outcomes for organizations.

VulnCheck gives organizations a tactical advantage by providing best-in-class exploit & vulnerability intelligence information. We have a sense of duty to protect the critical infrastructure we rely on including medical devices, power grids and telecommunication networks. We were founded in 2021 in Lexington, Massachusetts.

VulnCheck has a transparent, collaborative, and supportive culture - we are looking for people who have a growth mindset, are curious and innovative. Our team is smart, but humble, hardworking, and supportive.

VulnCheck is proud to be an Equal Employer Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. VulnCheck is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. *Even if your experience doesn’t perfectly align with the job description, we encourage you to apply—we value potential just as much as a perfect resume.

Skills Required

  • Ability to evaluate exploit proof-of-concepts (PoCs)
  • Familiarity with scripting languages
  • Experience with OSINT tools and resources
  • Understanding of indicators of compromise (IOCs) and how to identify them
  • Ability to assess credibility and validity of intelligence sources
  • Strong understanding of CVEs, including assignment and validation
  • Familiarity with CPE and scoring methodologies
  • Experience working with structured data formats (e.g., JSON)
  • High attention to detail and analytical rigor
  • Familiarity with end-of-life (EOL) software data
  • Experience with developer/security tooling (e.g., VS Code and extensions)
  • Familiarity with package ecosystems (NPM, NuGet, PyPI)
  • Python scripting skills
  • Experience with prompt engineering
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Lexington, Massachusetts
48 Employees
Year Founded: 2021

What We Do

VulnCheck helps organizations outpace adversaries with vulnerability intelligence that predicts avenues of attack with speed and accuracy. The VulnCheck team comprises a who's who of cybersecurity research, with decades of experience uncovering 100s of 0days and 10+ patents. VulnCheck's vulnerability and exploit intelligence equips defenders with the insights they need to focus resources on the vulnerabilities that matter most. That's why VulnCheck has been selected to power government agencies, large enterprises, and the industry's most innovative cybersecurity solutions, covering billions of assets around the world. See what you're missing at www.vulncheck.com.

Similar Jobs

Samsara Logo Samsara

Specialist Seller - Connected Maintenance - Public Sector

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
MA
4000 Employees
350K-350K Annually
In-Office or Remote
2 Locations
185619 Employees

Falcon Funded Logo Falcon Funded

UGC Creator - Morocco

Fintech • Financial Services
Remote
MA
125 Employees

DBS Bank Ltd Logo DBS Bank Ltd

Senior Officer, Spec

Fintech • Information Technology • Software • Financial Services
Remote
Centre, El-Hajeb, MAR
41000 Employees

Similar Companies Hiring

Rhymetec Thumbnail
Cloud • Information Technology • Consulting • Cybersecurity • Data Privacy
US
33 Employees
Copia Automation Thumbnail
Cybersecurity • Industrial
New York, New York
50 Employees
SEON Thumbnail
Artificial Intelligence • Cybersecurity
Budapest, Budapest
415 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account